api-gateway

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to interact with a vast array of external data sources, creating a significant surface for indirect prompt injection attacks.\n
  • Ingestion points: The agent reads potentially malicious content from dozens of external services, including emails (e.g., providers/kiro/.kiro/powers/api-gateway/references/outlook/README.md), chat messages (.../slack/README.md), and CRM records (.../hubspot/README.md).\n
  • Boundary markers: The reference documentation frequently includes "Privacy" and "Safety" warnings (e.g., in .../exa/README.md and .../fathom/README.md) advising the agent to treat returned content as untrusted input.\n
  • Capability inventory: The skill provides the agent with powerful capabilities across integrated services, including sending emails (.../resend/README.md), performing financial transactions (.../stripe/README.md), and deleting cloud storage files (.../dropbox/README.md).\n
  • Sanitization: Automated sanitization of ingested content is not specified in the provided instructions; the skill relies on the agent following the documented safety warnings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 11:51 PM
Security Audit — agent-trust-hub — api-gateway